Skip to content
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

Securityweek • September 23, 2026

F5 and CISA on Tuesday warned organizations that threat actors have been exploiting a critical-severity BIG-IP Access Policy Manager (APM) vulnerability as a zero-day.

The flaw is exploitable via malicious traffic sent to the appliance when “a BIG-IP APM access policy and an OAuth profile are configured on a virtual server,” F5 notes in its advisory .

Tracked as CVE-2026-94127 (CVSS score of 9.8), the bug allows unauthenticated attackers to achieve remote code execution (RCE) on a vulnerable deployment.

“We have learned that this vulnerability has been exploited,” F5 says, noting that it discovered the security defect internally.

According to the company, the issue can be triggered only when BIG-IP APM is configured as an OAuth Authorization Server, not on deployments using APM as an OAuth Client/Resource Server.

“The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure,” the company notes.

BIG-IP APM versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 are vulnerable, and F5 has released hotfixes. No other products are vulnerable, the company says.

Additionally, the company published three indicators of compromise (IoCs), noting that their combined and frequent appearance should be correlated to an attack.

Just as F5 published its advisory, CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities ( KEV ) list, urging federal agencies to patch it within three days, as mandated by BOD 26-04.

Related: Check Point Patches Exploited Management Server Zero-Day

Related: Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

Related: Malicious B-tree NPM Package Accumulates Millions of Downloads

Related: AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

Ionut Arghire is an international correspondent for SecurityWeek.

More from Ionut Arghire

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

Malicious B-tree NPM Package Accumulates Millions of Downloads

WordPress Patches ‘Click2Shell’ Vulnerability

Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer

RatHat Android Trojan Uses AI for Automation

CrowdSec Confirms Source Code Stolen in Supply Chain Attack

Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities

TigerByte Cyber Emerges From Stealth With $3 Million in Funding

Chrome 154 Patches 108 Vulnerabilities

A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk

Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm

Arista Urges Immediate Patching of Exploited VCO Zero-Day

ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report

Check Point Patches Exploited Management Server Zero-Day

BigCommerce Data Stolen via Ribon Apps Hack

Cyera Raises $400 Million at $12+ Billion Valuation

Virtual Event: Attack Surface Management Summit 2026

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Webinar: Building Continuous Authorization at Scale

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Flipboard Whatsapp Whatsapp Email

Extracted Entities

Attack Types (1)

Platforms (1)